Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 585780 - app-arch/lrzip-0.630: version bump
Summary: app-arch/lrzip-0.630: version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Yanestra
URL: http://ck.kolivas.org/apps/lrzip/lrzi...
Whiteboard:
Keywords:
: 587178 (view as bug list)
Depends on:
Blocks: 586132
  Show dependency tree
 
Reported: 2016-06-13 07:23 UTC by Yanestra
Modified: 2016-08-08 12:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yanestra 2016-06-13 07:23:37 UTC
0.630 contains a number of bug fixes, including security fixes.
Comment 1 Coacher 2016-06-13 13:03:26 UTC
Could you please point out security-related fixes?
Comment 2 Yanestra 2016-06-13 19:32:13 UTC
* Correct adding slash to control->tmpdir. off-by-one error

Environment settings could lead to arbitrary files being overwritten.
Comment 3 Coacher 2016-06-14 17:10:23 UTC
(In reply to Yanestra from comment #2)
> * Correct adding slash to control->tmpdir. off-by-one error
> 
> Environment settings could lead to arbitrary files being overwritten.
Discussion in https://github.com/ckolivas/lrzip/pull/38 states that this isn't really a security problem, but a harmless bug.
Comment 4 Hadrien Lacour 2016-06-15 10:13:55 UTC
There are maybe no security bugfix, but there's an incredibly annoying bug fixed, that prevented lrztar from being used on directories with whitespaces.
Comment 5 Yanestra 2016-06-15 15:03:25 UTC
Being unable to unpack larger multi-volume archives is also not so nice. That bug was fixed.
Comment 6 Coacher 2016-06-15 15:23:36 UTC
(In reply to johncarmack from comment #4)
> There are maybe no security bugfix, but there's an incredibly annoying bug
> fixed, that prevented lrztar from being used on directories with whitespaces.
I was asking about security problems because security vulnerabilities require security team involvement. There's currently no maintainer so this bump can take some time. If you want to speed things up and get that annoying bug fixed, you can contribute by maintaining this package yourself via proxy-maint team:
https://wiki.gentoo.org/wiki/Project:Proxy_Maintainers
Comment 7 Yanestra 2016-06-16 01:05:01 UTC
As far as I can see it's not more required than to rename the ebuild.
Comment 8 Coacher 2016-06-27 11:38:58 UTC
*** Bug 587178 has been marked as a duplicate of this bug. ***
Comment 9 Amy Liffey gentoo-dev 2016-07-06 16:56:34 UTC
committer	Amy Winston <amynka@gentoo.org>	2016-07-06 16:40:24 (GMT)
commit	8759c82ee21fb03b5044eac80c99d400ed706356

app-arch/lrzip: version bump 0.630 bug #585780
- Add static-libs useflag bug #490060
- Convert patch to p1
- Change homepage


I have made some changes to ebuild you submited. If you have any questions why etc don't be afraid to ask here by email or on irc.

Thanks :)